Fall 2015 Schedule

We will be discussing an alternative Risk Assessment method OCTAV Alegro, you can read more here.
Date
Chapter
Coverage
Readings
Assignment
Due Date
01/15/2015
Introduction




01/22/2015
Chapter 1
The Threat Environment
Read the 4 Threat Environment articles and be prepared to discuss in class.


01/29/2015
Readings:
COSO, COBIT
From the Frameworks & Standards page, read:* Internal Control - Integrated Framework (1992)* Internal Control - Integrated Framework (2011 Exposure Draft) external image pdf.png coso_draft_internal control framework.pdf


02/05/2015
Chapter 2
Planning & Policy
We will be discussing an alternative Risk Assessment method OCTAV Alegro, you can read more here.


02/12/2015
Module A
Networking Concepts



02/19/2015
No Class
Class Canceled



02/26/2015
Chapter 3
Cryptography
Read the Cryptography Readings from the Class Readings page


02/27/2015 to 03/04/2015
Exam 1 - Covers Chapters 1 -4 & Module A




03/05/2015
Chapter 4
Secure Networks



03/12/2015
Spring Break




03/19/2015
Chapter 5
Access Controls

Access Control Simulation
04/02/2015
03/26/2015
Readings
Passwords
Read the required readings from the Password section of the Class Readings


04/02/2015
No Class




04/09/2015
Chapter 6
Firewalls



04/16/2015
Chapter 7 & 8
Host Hardening & Application Security
Read the required Application Hardening articles section of the Class Readings
Read, The Future of Incident Response, by Bruce Schneier
Security in the News
04/23/2015
04/23/2015
Readings
SOX IT and other class Readings
Read the required readings from the IT Control and SOX section of the Class Readings

From the Frameworks & Standards page, read:* Enterprise Risk Management - Integrated Framework (2004)
  1. Cyberattack's abound yet companies tell SEC losses are few By Chris Strohm, Eric Engleman and Dave Michaels - Apr 3, 2013)
  2. Companies Hacked by Chinese Didn’t Disclose Attacks to Investors By By Chris Strohm, Dave Michaels and Sonja Elmquist - May 21, 2014)
  3. CF Disclosure Guidance: Topic No. 2 S.E.C. (This guidance provides the Division of Corporation Finance's views regarding disclosure obligations relating to cybersecurity risks and cyber incidents)
  4. SEC Cybersecurity Roundtable Archive Webcast
  5. SEC OCIE Cybersecurity Initiative (April 15, 2014)

  1. AICPA Top 5 Cybercrimes (2013)

  1. ERM for cloud computing (COSO)


04/24/2015 to 04/30/2015
Final Exam (5-10) and Readings